Trust & Compliance // SOC 2 Type II Ready · DPDP-Ready · In-Region Hosting

Enterprise trust & compliance.
Proof you can inspect.

Protecting your people shouldn't put their data at risk. KeenSec is SOC 2 Type II ready and DPDP-ready, hosts your data in-region, and your data never trains AI models.

  • SOC 2 Type II Ready
  • DPDP Act 2023 Ready
  • Zero Model Training
KeenSec Shield

Documented controls.
Evidence you can inspect.

Every protective layer is documented, so your team can review it instead of taking our word for it.

● Dedicated encryption keys per customer ● In-region hosting options ● Reported emails analysed, never kept for training
KEENSEC TRUST CENTRE // CONTROL REVIEW CONTINUOUS ASSURANCE
SECURITY TESTING Periodic Pentesting Application and infrastructure, with tracked remediation
SOC 2 READINESS SOC 2 Type II Ready Prepared toward a future SOC 2 Type II examination
SECURITY & READINESS STATUS LIVE CONTROLS
Assurance Standard Readiness

Controls, policies, and operational processes are prepared toward a future SOC 2 Type II examination.

SOC 2 Type II Ready
Vulnerability Remediation Risk-Based Prioritisation

Critical and high-severity vulnerabilities are prioritised and remediated on defined timelines.

Defined Timelines
Penetration Testing Application & Infrastructure

Periodic application and infrastructure penetration testing is performed to identify and remediate security weaknesses.

Periodic Pentesting
INDIAN DATA PROTECTION LAW DPDP Act 2023 Section 6 consent notices and Data Principal rights workflows
HOSTING LOCATION In-Region Hosting In-region hosting options on dedicated clusters
DATA RESIDENCY & EMPLOYEE RIGHTS IN-REGION ROUTING
Data Residency In-Region Hosting

Hosted on enterprise-grade cloud infrastructure with provider-managed physical security, resilient infrastructure, and controlled access to production systems.

In-Region
Data Principal Rights DPDP Act Sec. 6 & 11

Self-service data access, correction and verified erasure for employees.

Statutory Rights Active
Grievance Redressal DPO Escalation

Direct route to our Data Protection Officer, acknowledged within 72 hours.

DPO Channel Live
CERT-In Compliance Incident Reporting

Time-synchronised logs, 6-hour incident notification workflows and 180-day log retention.

CERT-In Directives Aligned
AI MODEL TRAINING Zero Training Never used to train AI, by contract and design
ENCRYPTION AES-256-GCM + KMS Dedicated keys per customer, rotated automatically
ENCRYPTION & AI DATA HANDLING ZERO-RETENTION ENFORCED
At-Rest Encryption Envelope Cryptography

Tenant-specific keys held in a hardware security module (FIPS 140-3 Level 3).

AES-256-GCM / 90-Day Rotation
In-Transit Security Forward Secrecy

TLS 1.3 on every public endpoint; mutual TLS between internal services.

TLS 1.3 + mTLS Inter-Service
Zero Model Training Contractual DPA

Your data never trains AI models, enforced with zero-retention settings.

Zero Foundation Training
Ephemeral Analysis 0s Persistence

Reported emails analysed in memory and wiped once the verdict is ready.

0-Second Disk Persistence

How we protect you

Five foundations of trust

Each one is backed by implemented, documented controls.

Tenant Isolated

Platform Security

Your data kept separate, encrypted and access-controlled.

  • Separate encryption per customer: Dedicated keys for every organisation, or bring your own key.
  • Role-based access & SSO: Granular permissions, SAML 2.0 SSO and SCIM directory sync.
  • Hardened containers: Short-lived and immutable, with automated image scanning.
  • Security testing: Periodic application and infrastructure penetration testing, with weaknesses tracked to remediation.
Zero Model Training

AI & Data Handling

Where your data goes, how long it stays, and what AI never does with it.

  • Never used for training: Reports, simulation results and platform data never train AI models.
  • Analysed, then discarded: Suspicious emails are analysed in memory and deleted once the verdict is ready.
  • Private AI connections: Zero-retention agreements; personal data masked first.
In-Region Hosting

Deployment & Integrations

Where we host, how we connect, and how we fit your stack.

  • In-region hosting options: Enterprise-grade cloud infrastructure, with data kept in the region you choose.
  • On-premises option: Deploy KeenSec inside your own environment when policy requires it.
  • Private connectivity: VPC peering and private links keep traffic off the public internet.
  • One-click reporting: Deployed centrally to the inbox your people already use.
  • SIEM & SOAR feeds: Webhooks, CEF syslog and REST APIs send events to your SIEM.
DPDP & SOC 2 Ready

Compliance Alignment

Audit mappings and exportable records for compliance teams.

  • DPDP Act 2023 readiness: Section 6 notices, purpose limitation and Data Principal rights.
  • Mapped to the standards: NIST SP 800-50 Rev. 1, ISO 27001 Annex A and CERT-In.
  • Tamper-evident audit trail: Checksummed logs, ready to export for auditors.
  • Contracts that protect you: A signed customer agreement, Data Processing Agreement (DPA) and NDA.
Live Evidence

Customer Evidence & Assurance

Proof you can hand to your auditor.

  • Evidence package on request: SOC 2 readiness summary, penetration testing overview and architecture documents, under NDA.
  • Ongoing governance: Quarterly security reviews, service availability reporting and open change logs.

Control library

Browse our security controls

Filter or search to see how each control works and what it maps to.

Data residency

Your data stays in-region.
Protected end to end.

In-region hosting options keep your data where your regulators expect it, aligned with CERT-In directions and the DPDP Act 2023.

KEENSEC DATA FLOW // IN-REGION PROCESSING ZERO DATA EGRESS
01

In-Region Intake

Reported emails arrive in-region, with no external hops.

TLS 1.3 / mTLS
02

In-Memory Analysis

Analysed in memory. Nothing written to disk or sent to third-party models.

Zero Retention
03

Encrypted Storage

Results stored in-region, encrypted with your own key.

AES-256-GCM Envelope
04

Direct SIEM Streaming

Events stream to your SIEM over encrypted webhooks or VPC peering.

Private Networking

Availability

What's available today

A clear line between generally available features and enterprise-dedicated options.

Capability Area Availability Deployment Scope Compliance & Readiness
Multi-Channel Attack Simulation Email, SMS & RCS, voice (IVR & agentic AI), WhatsApp, Microsoft Teams and Slack, plus QR, calendar, browser ransomware, attachment and credential attacks Generally Available In-Region Cloud & Dedicated Tenants SOC 2 Type II Ready · In-Region Hosting
Employee Reporting & Analysis One click in the inbox your people already use, checked against multiple threat-intelligence and reputation sources Generally Available Mail Add-In + In-Region Backend SOC 2 Type II Ready · Zero Data Persistence
Human Cyber Risk Intelligence Risk patterns by team, channel and department Generally Available Tenant Console & SIEM Feeds DPDP Ready · Role-Based Access
Targeted Awareness & Learning Video, micro-learning, assessments, guided learning, certificates and just-in-time lessons Generally Available Integrated LMS / In-Line Browser Delivery SCIM v2.0 Sync · NIST SP 800-50 Rev. 1 Aligned
Policy Manager Distribute policies, collect acknowledgements, automate reminders and escalations Generally Available Tenant Console SCIM v2.0 Sync · NIST SP 800-50 Rev. 1 Aligned
AI Studio Scenarios, landing pages and lessons, reviewed by a human Generally Available Tenant Console SCIM v2.0 Sync · NIST SP 800-50 Rev. 1 Aligned
KeenSec AI Threat Explanation Plain-language verdicts with evidence and confidence Generally Available Isolated AI Gateway Zero Model Training Guarantee
Enterprise SSO & Directory Sync SAML 2.0 / OIDC with automatic joiner and leaver sync Generally Available Directory & SSO Integration SOC 2 CC6.3 · Mandatory MFA
VPC Peering & Private Connectivity Traffic kept off the public internet Enterprise Dedicated Customer Virtual Private Cloud Network Isolation · Custom KMS BYOK
SECURITY DUE DILIGENCE

Need our SOC 2 readiness details or security documents?

Available to qualified security teams, auditors and CISOs under mutual NDA.

SOC 2 Type II Readiness Summary How our controls map to the Trust Services Criteria.
Security Architecture Overview Tenant isolation, encryption and key management, and access controls.
Penetration Testing Overview How we test the application and infrastructure, and track remediation.
DPDP Act Data Processing Addendum (DPA) Ready to sign, including our zero-model-training commitment.

Let’s connect the dots

Bring your requirements.
Inspect the evidence.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo